Over 1 Million WordPress Sites at Risk After Popular Plugin Hacked: OptinMonster Among Those Affected by CDN Supply Chain Attack



  • A vulnerability in the UpdraftPlus plugin on Awesome Motive’s marketing server allowed CDN compromise and malicious JavaScript injection
  • The malware targeted logged-in WordPress administrators, collecting tokens and creating fraudulent accounts to take full control.
  • Site owners are urged to check for fake administrator accounts (‘developer_api1’, ‘dev_xxxxxx’), hidden backdoor plugins, and rotate credentials/security lounges.

More than a million WordPress websites were at risk of being completely taken over, after a vulnerability in a plugin allowed a large-scale supply chain attack. The attack was detected over the weekend by the security team of e-commerce Sansec and later confirmed by the victim company.

According to researchers, hackers found and exploited a vulnerability in the UpdraftPlus WordPress plugin running on a marketing server belonging to Awesome Motive, the company behind several popular WordPress products, including OptinMonster, TrustPulse, and PushEngage.

Leave a Comment

Your email address will not be published. Required fields are marked *